Skip to content
  • Home Home Home, current page.
  • About

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
Suggested users
  • Verified accountProtected Tweets @
  • Verified accountProtected Tweets @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English UK
    • Español
    • Filipino
    • Français
    • Hrvatski
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Ελληνικά
    • Български език
    • Русский
    • Српски
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in
    Have an account?
    · Forgot password?

    New to Twitter?
    Sign up
perrymetzger's profile
Perry E. Metzger
Perry E. Metzger
Perry E. Metzger
@perrymetzger

Tweets

Perry E. Metzger

@perrymetzger

Mad Scientist, Bon Vivant, and Raconteur.

Joined March 2010

Tweets

  • © 2019 Twitter
  • About
  • Help Center
  • Terms
  • Privacy policy
  • Cookies
  • Ads info
Dismiss
Previous
Next

Go to a person's profile

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
Suggested users
  • Verified accountProtected Tweets @
  • Verified accountProtected Tweets @

Promote this Tweet

Block

  • Tweet with a location

    You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more

    Your lists

    Create a new list


    Under 100 characters, optional

    Privacy

    Copy link to Tweet

    Embed this Tweet

    Embed this Video

    Add this Tweet to your website by copying the code below. Learn more

    Add this video to your website by copying the code below. Learn more

    Hmm, there was a problem reaching the server.

    By embedding Twitter content in your website or app, you are agreeing to the Twitter Developer Agreement and Developer Policy.

    Preview

    Why you're seeing this ad

    Log in to Twitter

    · Forgot password?
    Don't have an account? Sign up »

    Sign up for Twitter

    Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

    Sign up
    Have an account? Log in »

    Two-way (sending and receiving) short codes:

    Country Code For customers of
    United States 40404 (any)
    Canada 21212 (any)
    United Kingdom 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Ireland 51210 Vodafone, O2
    India 53000 Bharti Airtel, Videocon, Reliance
    Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italy 4880804 Wind
    3424486444 Vodafone
    » See SMS short codes for other countries

    Confirmation

     

    Welcome home!

    This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.

    Tweets not working for you?

    Hover over the profile pic and click the Following button to unfollow any account.

    Say a lot with a little

    When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.

    Spread the word

    The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.

    Join the conversation

    Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.

    Learn the latest

    Get instant insight into what people are talking about now.

    Get more of what you love

    Follow more accounts to get instant updates about topics you care about.

    Find what's happening

    See the latest conversations about any topic instantly.

    Never miss a Moment

    Catch up instantly on the best stories happening as they unfold.

    Perry E. Metzger‏ @perrymetzger Aug 15

    Your bluetooth device (headset, 2FA fob, keyboard, whatever) turns out to be insecure. And not fixable. Third parties can force your key length down to one byte. What a clusterfuck.https://knobattack.com/ 

    7:28 PM - 15 Aug 2019
    • 259 Retweets
    • 442 Likes
    • Austin Williams ILya Z SODA David Maxwell Stephen Malina polyminer1 Z3FixXx Rob EL Mike
    25 replies 259 retweets 442 likes
      1. New conversation
      2. PleaseSavePlanet‏ @icabodsmane Aug 17
        Replying to @perrymetzger

        It may also cause cancer, so there’s that as well.

        1 reply 0 retweets 0 likes
      3. Perry E. Metzger‏ @perrymetzger Aug 17
        Replying to @icabodsmane

        Horseshit.

        1 reply 0 retweets 0 likes
      4. PleaseSavePlanet‏ @icabodsmane Aug 17
        Replying to @perrymetzger

        https://www.miamiherald.com/news/nation-world/world/article227503539.html …

        1 reply 0 retweets 0 likes
      5. Perry E. Metzger‏ @perrymetzger Aug 17
        Replying to @icabodsmane

        I don't care if 5000 people or 50 million people who haven't read the literature sign an appeal. This has been studied intensively for decades. There are no good studies supporting the idea and lots of good studies saying there's no risk.

        1 reply 0 retweets 0 likes
      6. Perry E. Metzger‏ @perrymetzger Aug 17
        Replying to @perrymetzger @icabodsmane

        There is only one question in science: it isn't how many people believe things, or how good the credentials of someone who believes are. If you test a hypothesis, and it isn't supported by experiment, it's wrong. Who cares if 250 ignorant doctors signed something?

        1 reply 0 retweets 0 likes
      7. PleaseSavePlanet‏ @icabodsmane Aug 17
        Replying to @perrymetzger

        I got a nice flavorable pack of cigarettes to sell ya.

        1 reply 0 retweets 0 likes
      8. Perry E. Metzger‏ @perrymetzger Aug 17
        Replying to @icabodsmane

        Studies clearly conclude that cigarettes cause cancer. Why do you believe those but not the ones that say radio frequency emissions don’t cause cancer? Is there some reason you trust science on one and not the other?

        0 replies 0 retweets 0 likes
      9. End of conversation
      1. New conversation
      2. 𝓓𝓪𝓷𝓲𝓮𝓵 𝓚𝓻𝓪𝓯𝓽‏ @wamdamdam Aug 16
        Replying to @perrymetzger @blacktar

        Actually that doesn't sound like it's unfixable, or do you have any other resources? All that needs to be done is (out of specification) do not allow small keylengths. Yeah, that needs an update on all devices. https://www.kb.cert.org/vuls/id/918987/  even mentions a solution.

        2 replies 0 retweets 7 likes
      3. Vidar Andersen‏ @blacktar Aug 16
        Replying to @wamdamdam @perrymetzger

        There’s theory and there is real life. I guess the majority of BT devices are not auto-updatable (if at all), hence will never be updated, I recon.

        2 replies 0 retweets 8 likes
      4. Quest For The Snark‏ @Quest4TheSnark Aug 16
        Replying to @blacktar @wamdamdam @perrymetzger

        But if the phones / computers on the other end of the connection are updated to disallow small keys, do we really care that the BT devices don't update?

        1 reply 0 retweets 6 likes
      5. Vidar Andersen‏ @blacktar Aug 16
        Replying to @Quest4TheSnark @wamdamdam @perrymetzger

        Isn’t that naïve? As long as I can still force the BT IoT devices to accept small keys I can snarf and hijack them for fun & profit, can’t I?

        1 reply 0 retweets 2 likes
      6. Quest For The Snark‏ @Quest4TheSnark Aug 16
        Replying to @blacktar @wamdamdam @perrymetzger

        As I understand it this attack doesn't let you pair with a device, but attacks an existing paired connection. If the IoT devices are talking to each other then you could snarf their communications, but if they talk to a phone/computer then my proposal would stop you.

        2 replies 0 retweets 5 likes
      7. Perry E. Metzger‏ @perrymetzger Aug 16
        Replying to @Quest4TheSnark @blacktar @wamdamdam

        What fraction of Android phones get updates these days? As for desktops, I have a friend, a very smart person, who whines at me when I suggest that they need to update their computer. People will be making hay from this for years.

        1 reply 0 retweets 6 likes
      8. Perry E. Metzger‏ @perrymetzger Aug 16
        Replying to @perrymetzger @Quest4TheSnark and

        Another big problem: I doubt that the people creating protocols are finally going to learn their lesson. Complexity kills, and radio links, which are exposed attack surfaces, keep getting more and more complicated, often needlessly.

        2 replies 0 retweets 6 likes
      9. Perry E. Metzger‏ @perrymetzger Aug 16
        Replying to @perrymetzger @Quest4TheSnark and

        BTW, one wonders if man-in-the-middle attacks are possible here that would only be fixable if both ends were updated. I need to think on that.

        0 replies 0 retweets 4 likes
      10. End of conversation
      1. New conversation
      2. Erik Fair‏ @skeptech Aug 15
        Replying to @perrymetzger

        I knew there was probably a good reason to keep using wired keyboards.

        1 reply 0 retweets 7 likes
      3. Perry E. Metzger‏ @perrymetzger Aug 16
        Replying to @skeptech

        I refuse to use wireless keyboards and mice. Always have. I don't trust them because I never trusted the wireless protocol specs.

        2 replies 0 retweets 5 likes
      4. Stefan‏ @DigitalStefan Aug 16
        Replying to @perrymetzger @skeptech

        Whilst they haven’t a perfect history, Logitech with their unifying receiver are currently a very acceptable way of ‘doing’ wireless keyboards and mice.

        2 replies 0 retweets 0 likes
      5. Perry E. Metzger‏ @perrymetzger Aug 16
        Replying to @DigitalStefan @skeptech

        What makes you think those are secure?

        1 reply 0 retweets 1 like
      6. Perry E. Metzger‏ @perrymetzger Aug 16
        Replying to @perrymetzger @DigitalStefan @skeptech

        (Let me put that differently: they've been attacked successfully. I don't see why we should prefer their security.)

        1 reply 0 retweets 1 like
      7. Stefan‏ @DigitalStefan Aug 16
        Replying to @perrymetzger @skeptech

        Logitech pushed out a firmware update to remove the exploit. None of the OEMs are perfect, but how many even provide an option to update the firmware? Logitech at least reacted in the correct way.

        0 replies 0 retweets 0 likes
      8. End of conversation

    Loading seems to be taking a while.

    Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

      Promoted Tweet

      false

      • © 2019 Twitter
      • About
      • Help Center
      • Terms
      • Privacy policy
      • Cookies
      • Ads info